Agent skill

Enrich Ioc

by dandye in dandye/ai-runbooks

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

Apache-2.0Auto-check passedSecurity

Install Enrich Ioc

skills CLI
$ npx skills add dandye/ai-runbooks --skill enrich-ioc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dandye/ai-runbooks enrich-ioc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dandye/ai-runbooks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enrich-ioc .claude/skills/enrich-ioc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enrich-ioc
GitHub stars
127
Token cost
~702 tokens
SKILL.md length
211 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

  • Works in 3 steps: GTI Enrichment → SIEM Entity Lookup → SIEM IOC Match Check
  • You need to look up reputation and context for an indicator using GTI and SIEM
  • SKILL.md covers Inputs, Workflow, Required Outputs and Quick Reference
  • Reaches bad.url

What it does

Enrich Ioc is an agent skill from dandye/ai-runbooks. Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summary, and IOC match status.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations and OSINT. It works with Model Context Protocol. The licence is Apache-2.0.

When your agent uses it

  • You need to look up reputation and context for an indicator using GTI and SIEM
  • Tasks that involve Security operations
  • Tasks that involve OSINT

Example prompts

  • “/enrich-ioc”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. GTI Enrichment
  2. SIEM Entity Lookup
  3. SIEM IOC Match Check

What it can do on your machine

Read from SKILL.md and the folder at commit 72a6863. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • bad.url

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Enrich Ioc loads about 702 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 211 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~702

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dandye/ai-runbooks at commit 72a6863, republished under its Apache-2.0 licence (© dandye). 211 words, ~702 tokens.

Download SKILL.mdSave it as .claude/skills/enrich-ioc/SKILL.md (or your agent's skills folder).
name
enrich-ioc
description
Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summary, and IOC match status.
type
Skill
required_roles.chronicle
roles/chronicle.viewer
required_roles.gti
GTI Standard
personas
tier1-analyst, tier2-analyst, tier3-analyst, threat-hunter, incident-responder
generated.by
human:mlutx
generated.at
2026-01-13T16:30:44-06:00

Enrich IOC Skill

Perform standardized enrichment for a single Indicator of Compromise (IOC) using Google Threat Intelligence (GTI) and Chronicle SIEM.

Inputs

  • IOC_VALUE - The indicator value (e.g., "198.51.100.10", "evil-domain.com", "abcdef123456...", "http://bad.url/path")
  • IOC_TYPE - The type: "IP Address", "Domain", "File Hash", or "URL"

Workflow

Step 1: GTI Enrichment

Based on IOC_TYPE, call the appropriate GTI tool:

IOC TypeToolExample
IP Addressgti-mcp.get_ip_address_reportget_ip_address_report(ip_address="198.51.100.10")
Domaingti-mcp.get_domain_reportget_domain_report(domain="evil-domain.com")
File Hashgti-mcp.get_file_reportget_file_report(hash="abcdef123...")
URLgti-mcp.get_url_reportget_url_report(url="http://bad.url/path")

Store key findings in GTI_FINDINGS:

  • Reputation score
  • Classification (malicious, suspicious, clean)
  • Key relationships (contacted domains, IPs, etc.)
  • Associated malware families or campaigns

Error Handling: If GTI fails (quota exceeded, IOC not found), note the limitation and proceed with SIEM enrichment.

Step 2: SIEM Entity Lookup
secops-mcp.lookup_entity(entity_value=IOC_VALUE)

Store in SIEM_ENTITY_SUMMARY:

  • First/last seen timestamps
  • Related alerts
  • Associated assets/users
Step 3: SIEM IOC Match Check
secops-mcp.get_ioc_matches()

Check if IOC_VALUE appears in results. Store Yes/No in SIEM_IOC_MATCH_STATUS.

Required Outputs

After completing this skill, you MUST report these outputs:

OutputDescription
GTI_FINDINGSSummary of GTI report (reputation, classification, relationships)
SIEM_SUMMARYSIEM entity context (first/last seen, related alerts)
IOC_MATCH_STATUSYes/No - whether IOC appears in recent threat feed matches
THREAT_SCORENumerical threat score (0-100) based on GTI reputation
MALICIOUS_CONFIDENCEConfidence level: high, medium, low, or none

Quick Reference

GTI Tools:

  • get_ip_address_report(ip_address)
  • get_domain_report(domain)
  • get_file_report(hash)
  • get_url_report(url)

SIEM Tools:

  • lookup_entity(entity_value)
  • get_ioc_matches()

© dandye, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/enrich-ioc of dandye/ai-runbooks.

Open the folder on GitHubat commit 72a6863

Compare with similar skills

Enrich Ioc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enrich Ioc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enrich Ioc this skilldandye/ai-runbooks127—~702Automated safety check: PassApache-2.0
Threat Intelligence OSINTzhaoxuya520/reverse-skill41k1 repos~1kAutomated safety check: PassMIT
Threat Database UpdateFlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0
Ecs Operation Reviewaws/tools-for-devops-agent103—~4.8kAutomated safety check: PassApache-2.0
Implementing Stix Taxii Feed Integrationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Threat Intelligencesickn33/agentic-awesome-skills47k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    41k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Threat Database Update

    FlorianBruniaux/claude-code-ultimate-guide

    Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

    6.1k GitHub stars~680 tokensUpdated today
    SecurityAuto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Implementing Stix Taxii Feed Integration

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Threat Intelligence

    sickn33/agentic-awesome-skills

    Authorized OSINT and cyber threat intelligence: enriching IOCs, campaigns, impersonation, scams, and threat-actor profiles from public sources with defined boundaries.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check passed
  • Automating Ioc Enrichment

    mukul975/Anthropic-Cybersecurity-Skills

    Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from dandye/ai-runbooks

All 27 skills in this repo
  • Close Case Artifact

    dandye/ai-runbooks

    Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~615 tokensUpdated 1 mo ago
    Auto-check passed
  • Correlate Ioc

    dandye/ai-runbooks

    Check for existing SIEM alerts and case management entries related to IOCs.

    127 GitHub stars~624 tokensUpdated 1 mo ago
    Auto-check passed
  • Deep Dive Ioc

    dandye/ai-runbooks

    Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Find Relevant Case

    dandye/ai-runbooks

    Search for existing cases related to specific indicators or entities.

    127 GitHub stars~562 tokensUpdated 1 mo ago
    Auto-check passed
  • Full Alert Triage

    dandye/ai-runbooks

    Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Hunt Apt

    dandye/ai-runbooks

    Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Enrich Ioc

What does Enrich Ioc do?

Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Enrich Ioc is an agent skill from dandye/ai-runbooks. Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

When should I use Enrich Ioc?

Enrich Ioc fits situations like: you need to look up reputation and context for an indicator using GTI and SIEM; tasks that involve Security operations; tasks that involve OSINT.

How do I install Enrich Ioc in Claude Code?

Run `npx skills add dandye/ai-runbooks --skill enrich-ioc -a claude-code`. Or copy the skill folder (skills/enrich-ioc in dandye/ai-runbooks) into .claude/skills/enrich-ioc in your project. Claude Code loads it when a task matches its description.

How do I install Enrich Ioc in Codex?

Run `npx skills add dandye/ai-runbooks --skill enrich-ioc -a codex`. Or copy the skill folder (skills/enrich-ioc in dandye/ai-runbooks) into .agents/skills/enrich-ioc in your project. Codex loads it when a task matches its description.

Can I use Enrich Ioc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dandye/ai-runbooks --skill enrich-ioc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enrich-ioc, .gemini/skills/enrich-ioc, .github/skills/enrich-ioc and .opencode/skills/enrich-ioc in your project.

What does Enrich Ioc need to run?

SKILL.md names no scripts, command-line tools or credentials: Enrich Ioc is instructions for the agent only.

Does Enrich Ioc access the network?

SKILL.md names 1 domain. In commands or code: bad.url; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Enrich Ioc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enrich Ioc use?

Enrich Ioc is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enrich Ioc use?

About 702 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Enrich Ioc?

Skills that share tags, products or a category with Enrich Ioc: Threat Intelligence OSINT (zhaoxuya520/reverse-skill, 41k stars), Threat Database Update (FlorianBruniaux/claude-code-ultimate-guide, 6.1k stars), Ecs Operation Review (aws/tools-for-devops-agent, 103 stars) and Implementing Stix Taxii Feed Integration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enrich Ioc?

dandye (a GitHub user) maintains it in dandye/ai-runbooks, which has 127 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 14, 2026.

Source: dandye/ai-runbooks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.